Last updated: August 21, 2026 Effective date: June 12, 2026
What we collect
Your account info: name, email, password, subscription tier, state of residence. Information you enter about your children and family: each child's name, grade, district, special-education status, and other context you choose to add. One account can hold up to four Child Profiles; everything below is scoped per child. Documents and notes you upload: IEPs, school emails and letters, prior written notices, progress reports, report cards, ARD/IEP meeting notes, behavior plans, journal entries, AI prompts, AI outputs you save. For the educational records you upload: the body text of the document, extracted and stored in our database, encrypted at rest with an Advoly-controlled key. This lets the Pocket Advocate and other AI features cite specific language from your records - for example, a goal in your child's IEP or a sentence in a progress report. A small amount of derived data we create to keep accounts honest: the parent/guardian names and household address listed in an uploaded IEP (used to enforce the one-household account rule), and a per-message on-topic/off-topic flag on Pocket Advocate messages (used to deter account sharing). Section 5 explains both in plain language. Technical info from your device: IP address, device type, OS, app version, usage statistics in aggregate.
What we don't do
We do not sell or share your personal information for cross-context behavioral advertising. We do not train AI models on your data. Advoly does not develop or train AI models. Our AI provider does not train its models on Advoly's commercial-API traffic. The current AI provider is named on our Subprocessors page. Advoly is for educational records. We accept the records of your child's education and special education advocacy - IEPs, prior written notices, behavior intervention plans, progress reports, report cards, ARD/IEP meeting notes, 504 plans, and school correspondence. Educational evaluations are accepted and stored in your record, and our AI features read them the same way they read your child's other school records. Maya will tell you what a report says, including scores, and explain in general terms what a kind of assessment measures. She will not interpret your child's results, offer a diagnosis, or second-guess your evaluator. Medical records are not accepted. See §10.1. We do not accept medical records, prescription information, insurance documents, treatment notes, hospital records, or other documents whose primary purpose is medical care; if our system identifies an upload as a medical record, we will not save it. We do not share your records with marketers, advertisers, data brokers, or any third party for that party's own purposes. We do not use your data to build advertising profiles or to target you with ads. Advoly has no advertising at all. We are not a HIPAA-covered entity. HIPAA does not apply to us by default. We apply HIPAA-grade encryption and access controls voluntarily. We are not a school. FERPA governs schools, not parent-side tools. The records you upload are your own copies, held under your parental rights.
Your controls
See, export, correct, or delete your data at any time from your account or by emailing support@advoly.com. Download a complete JSON archive of your account - covering every Child Profile on it - through the in-product export endpoint described in §14. Delete your account and all data: hard-deleted from production within 30 days (encrypted body text deletes immediately by database cascade), and from our hosting platform's backups within roughly 14 days (and in no event later than 90 days). Subprocessor retention windows that continue downstream of Advoly are described in §12. Withdraw consent or opt out where applicable. We honor Global Privacy Control (GPC) signals from your browser. Texas, California, and other state-specific rights enumerated in Section 14.
One more thing, because we're in beta
During our invite-only beta, Advoly staff may review beta account content - including chats and documents - to diagnose issues and make sure the AI is behaving safely. That access is logged, and §2.1 describes it fully. If you're not comfortable with that, the honest answer is: don't join the beta. After beta, this access ends.
The detailed policy follows. The detailed policy is the legally operative text; this summary is a guide to it.
This Privacy Policy describes how Advoly LLC, a Texas limited liability company at 5900 Balcones Drive, Suite 100, Austin, TX 78731 ("Advoly," "we," "us," or "our"), collects, uses, and discloses information when you use our mobile and web applications and the Advoly website at advoly.app (collectively, the "Services").
This Privacy Policy applies to you when you visit our website, create an account, use the mobile or web app, contact our support team, or otherwise interact with the Services.
Advoly is currently in an invite-only beta. We want beta parents to know exactly what that means for their data, without euphemism:
What we may look at. During the beta, Advoly staff may review the content of beta accounts - including your conversations with the Pocket Advocate, the documents you upload and their extracted text, your Events Log entries, and the AI's outputs - to diagnose problems, verify that the AI is answering accurately and behaving safely, and improve the product. Why. A pre-launch product serving stressed parents and children's records has to be watched closely while it is young. Reviewing real interactions is how we catch the AI being wrong, confusing, or unsafe before it matters. How it is controlled. Beta review access is limited to authorized Advoly personnel, is logged, and is used only for diagnosis, safety, and product improvement - never for marketing, never shared outside Advoly except as this policy otherwise allows (for example, §8). How to opt out. Don't join the beta. We say that plainly because it is the real answer: beta participation and this level of observability come together. This section is also presented to you at beta signup, so the choice is in front of you before any of your data is. When it ends. When the beta ends, this section will be retired and routine staff access will narrow to the posture described in §13 (restricted, logged, exception-based).
We collect information in four ways: information you provide, information we derive from what you provide, information we receive automatically, and information we receive from third parties.
Information you provide. When you create an account and use the Services, you provide:
Account information: name, email address, password, state of residence, and account preferences. Subscription and billing information: subscription tier, payment method (handled by Stripe; we do not see or store your full payment card details). Profile and family information: your name and role (parent, legal guardian, etc.), and for each Child Profile you set up in Advoly (up to four per account), that child's name, date of birth or grade, school district, special education status, and other information you choose to enter. Each child's records are scoped to that child's profile. User Content: documents you upload (IEPs, school emails, letters, prior written notices, progress reports, report cards, behavior plans, ARD/IEP meeting notes, and similar educational records), journal entries you make in the Events Log, profile data you save, prompts you type into the Pocket Advocate AI, and AI outputs you choose to save. For each document you upload, we additionally collect and store:
The original file (PDF, Word, image, etc.) in our document storage provider, scoped to the relevant Child Profile. For educational records, the extracted body text of the document, stored in a separate encrypted database table (see §10 and §13). Educational evaluations are handled like other educational records: their text is extracted and stored encrypted, and is available to AI features for the child they belong to. Medical records are refused at upload. §10.1 describes all three categories, including what happens if a document is mislabeled. For PDFs that are image-based (scans without an OCR layer, photos of physical documents), text extraction is performed by sending the PDF - including its images - to our AI provider for vision-based extraction. The resulting text is stored the same way text-extractable content is: encrypted at rest. See §5 for the data flow and §13 for the encryption posture. Document metadata (filename, document type, date you assigned, status flags, your notes on the document).
Communications: messages you send to support, feedback, and feature suggestions.
Information we derive. Three kinds of information are created by Advoly from what you provide, for the integrity purposes described in §4 and §5:
Family-identity fields. When you upload an IEP, our servers send the document text to our AI provider to extract the parent/guardian names and the household address listed in it. We store those fields on the Child Profile. They are used to check that the Child Profiles on one account belong to the same household - see §5. Message relevance flags. Each message you send to the Pocket Advocate is classified by our AI provider as on-topic or off-topic relative to the active Child Profile, and the resulting flag is stored with the message - see §5. Extracted student name. When you upload a document, the student name listed in it is extracted and stored on that document's record, so it can be compared against the Child Profile you are working in - see §5.6.
Information we receive automatically. When you use the Services, we automatically collect technical information including IP address, device type, operating system, browser, app version, language, and usage information about which pages and features you use and when.
Information from third parties. If you choose to authenticate using a third-party identity provider (such as Apple Sign-In or Google Sign-In, where supported), we receive limited account information from that provider as authorized by you.
Sensitive categories. Some of the information you upload to Advoly relates to your child's disability, evaluations, health, behavior, or education. We treat this information as sensitive and apply elevated protections. We do not use sensitive information for advertising, profiling, or any purpose other than providing the Services to you.
Advoly runs a public waitlist at advoly.app/waitlist for people who cannot yet create an account, including residents of states where Advoly is not open. Someone on the waitlist has no Advoly account and is not a user of the Services.
From the waitlist form we collect only:
Email address (required). State of residence (required). An optional one-line answer about what you would want help with.
We collect nothing else about waitlist members. No child information, no records or documents, no account data, and no cross-app or cross-site tracking of waitlist members.
Purpose. We may use waitlist contact information to notify you when Advoly becomes available where you live, and to send you information, guidance, and promotional material about Advoly. Every such email carries an unsubscribe link, and unsubscribing stops them.
We do not sell waitlist information, and we do not share it with third parties for those parties' own purposes.
The optional free-text answer is treated more narrowly than the email address. We may use it in aggregate and de-identified form, for example to describe what parents most commonly ask about. We will not publish or quote any individual's response, in marketing or anywhere else, without that person's permission.
We use the information we collect to:
Provide the Services to you. Run your account, store your records, generate AI responses to your prompts, deliver email and letter drafts, present the Document Tracker checklist, and operate every other feature you use. Assemble grounding context for AI features. When you use an AI feature, we read decrypted body text from the educational records in the active Child Profile on our servers, combine it with that child's profile, intake, Events Log, and other context, and send the combined "grounding context" to our AI provider along with your prompt. This lets the AI cite specific language from your records. See §5 and §10.1 for what is and is not intended to be included. Protect the integrity of the Services. Advoly accounts are for one household, with up to four Child Profiles. To keep that rule meaningful - and to keep subscription pricing fair for the parents who follow it - we use the two derived-data flows described in §5: family-identity fields extracted from uploaded IEPs (checked across the Child Profiles on an account), and relevance flags on Pocket Advocate messages (to detect patterns that look like account sharing). A human at Advoly reviews the underlying data only when the automated check flags a mismatch or a pattern; routine use is automated and narrow. Improve and operate the Services. Diagnose technical issues, monitor performance, prevent fraud and abuse, and develop new features. We may use aggregated, de-identified usage statistics - never your User Content or sensitive information - to understand how the Services are used in general. During the beta, the broader (and disclosed, and logged) staff review described in §2.1 also serves this purpose. Communicate with you. Respond to support requests, send transactional emails about your account and subscription, send security alerts, and (if you have opted in) send product updates. You can unsubscribe from product update emails at any time. Transactional and security emails will continue while your account is active. Comply with legal obligations. Respond to lawful subpoenas, court orders, regulatory requirements, and similar legal demands, consistent with the practices described in Section 8 - and make reports that the law requires us to make, including the child-safety reports described in Section 8.
We do not use your User Content, your sensitive information, or your AI prompts and outputs to train AI models, ours or any third party's. See Section 5.
Advoly uses a third-party AI provider's commercial API to power AI features including the Pocket Advocate, IEP Audit, Meeting Prep, Draft Emails, and document analysis, and for the supporting flows described below. The current provider is named on our Subprocessors page (advoly.app/subprocessors). There are four distinct ways your data can flow to our AI provider, and we describe each:
You type a prompt or run an AI tool. Our servers assemble a grounding context for the request, scoped to the active Child Profile. The grounding context is built from that child's account record (profile, child information, intake answers, Events Log entries) and from the decrypted body text of relevant educational records. Educational evaluations are included in the grounding context on the same terms as other educational records. Medical records are refused at upload and are not present in the body-text store at all. The body-text filter runs before decryption - documents not eligible for AI body-text use are excluded before any decryption call - with the honest caveat that eligibility is governed by the document's assigned type, which you select at upload and which may be mislabeled (§10.1). The grounding context and your prompt are sent from our servers to our AI provider's commercial API over an encrypted connection. The AI provider processes the request and returns a response. Under our commercial agreement with the AI provider, the provider does not use the request or the response to train its models. As is standard for commercial AI APIs, the provider retains the request and the response for a limited period for abuse-monitoring and trust-and-safety purposes before deletion. The provider's current published retention window is described on our Subprocessors page. We return the response to your app, and we store it as User Content in your account if you save it. For AI tools that produce a saved artifact (e.g., the IEP Audit), we store the AI-generated analysis as a separate Document Tracker entry, linked to the source document.
When you upload a document, you select its type (IEP, school email, progress report, and so on). The document's type controls how the system handles it (§10.1): which documents are eligible for body-text extraction and AI features, and which are not processed. We do not currently use AI to identify document types; if we introduce automated type identification to catch mislabeled documents, we will update this policy before it ships.
If the document type you select (or the document's filename) identifies an upload as a medical record, the document is not saved to your account, and you are shown a message explaining why. Identification is best-effort; the contractual rule in our Terms of Service (§11.1 - don't upload medical records) applies regardless of what the system catches.
Some documents parents upload - scans without an embedded text layer, photos taken of physical documents - cannot be parsed for text by our own extraction software. When this happens, the document (including the images it contains) is sent to our AI provider's vision capability for text extraction. The extracted text is returned to us, encrypted at rest with our Advoly-controlled key, and stored the same way text-extracted documents are stored. Whether a document enters this OCR flow is governed by its assigned document type; a mislabeled document could be OCR'd when it should not have been - §10.1 describes the correction and deletion remedies. The same AI-provider retention window described above applies to OCR requests. We use only our AI provider for OCR; we do not currently use any other OCR vendor.
When you upload an IEP, our servers send the document text to our AI provider to extract the parent/guardian names and household address listed in the document. Those fields are stored on the Child Profile. Here is the honest reason: an Advoly account is for one household, with up to four Child Profiles, and our pricing depends on that rule meaning something. The extracted fields are compared across the Child Profiles on an account; when the profiles on one account don't appear to belong to the same household, the mismatch is flagged for review by an Advoly admin - and that is the only time a human looks at these fields. The extraction request is processed under our AI provider's commercial-API terms (no training; standard retention window). The fields live and die with the Child Profile: delete the profile or the account, and they are deleted with it (§12).
Each message you send to the Pocket Advocate is also classified by our AI provider for relevance to the active Child Profile - is this conversation about this child's education, or about something (or someone) else entirely? The classification result is stored as a per-message flag alongside your chat history. A persistent off-topic pattern can produce an in-app reminder, and a pattern that looks like account sharing (for example, conversations that consistently describe a different child than the active profile) can be flagged for review. The classification does not change the Pocket Advocate's answer to you, and a single off-topic message - parents are human, conversations wander - does nothing at all. The classification request contains your message text and is processed under our AI provider's commercial-API terms (no training; standard retention window). The flags are retained as long as the chat history they describe and are deleted with it (§12).
When you upload a document, our servers send the document text to our AI provider to extract the student name listed in it. That name is stored on the document's own record. It is then compared against the Child Profile you are working in. If the two do not appear to match, you are shown a confirmation before an IEP Audit or a Document Decode runs on that document, and the document's body text is withheld from AI features until you confirm. This is a protection against a document being read into the wrong child's record, and we mean that affirmatively: it exists so one child's information does not end up shaping answers about another child. It has honest limits rather than being a guarantee. It depends on the document actually naming a student in a readable, clearly labeled way. When a document does not, the check returns no signal and nothing is blocked or flagged. Educational evaluations are checked against your Child Profile the same way every other document is. If a report names a different student, its text is withheld from AI features until you confirm it belongs to your child. The extracted name lives and dies with the document: delete the document or your account, and it is deleted with it (§12). The extraction request is processed under our AI provider's commercial-API terms (no training; standard retention window), the same as the other flows described in this section.
Two AI privacy commitments
Advoly does not train AI models on your data. Advoly LLC does not develop or train AI models, and we do not retain your data for any future training of any model we might build. Our AI provider does not train its models on your data either. This is the contractual position with our current AI provider and is the operative AI privacy commitment in the Services.
Important nuance on retention
When you delete a document or your account from Advoly, we delete the document and its extracted body text from our live systems by database cascade, and from our backups within Advoly's backup horizon (see §12). However, the AI provider's request-and-response retention window - which exists for abuse-monitoring purposes on requests already sent - runs independently and continues on the AI provider's own schedule. We do not control the AI provider's retention timer for requests already sent. The current window for the current provider is described on our Subprocessors page.
Other commitments
No data sale. We do not sell, license, or otherwise commercially share your data with any third party for that party's own purposes. No advertising profiles. We do not build advertising profiles. We do not allow advertising networks to target you based on your child's information. Advoly has no advertising at all.
For the current AI provider's identity, the provider's published terms, and any current retention specifics, see advoly.app/subprocessors.
We use a small set of trusted third-party service providers ("subprocessors") to operate the Services, including our AI provider, our database and backend host (which also hosts our document file storage and our key-management vault), our payments processor, our email delivery provider, and (where used) error monitoring and product analytics providers.
The full current list - with each subprocessor's name, role, data categories processed, location, and a link to the subprocessor's published privacy posture - is published at advoly.app/subprocessors. We update that page when our subprocessors change. For material additions or substitutions in a sensitive role (AI processing, database hosting, document storage, or key management), we aim to provide at least 30 days' advance notice where practicable - through the subprocessors page, by email to active paid subscribers, and to anyone who has subscribed to subprocessor notifications. For changes required for security, legal compliance, or service continuity, notice may be shorter or may follow the change. To subscribe to subprocessor change notifications, email support@advoly.com with the subject "Subscribe to subprocessor notifications."
We do not sell your information. We do not share your User Content with marketers, advertisers, researchers, schools, school districts, or any other party for that party's own purposes.
We share information only in these circumstances:
With subprocessors. As described in Section 6, our subprocessors process information on our behalf, under written data processing agreements that restrict their use. With you and at your direction. If you use a feature that shares information with someone else (for example, exporting a document to email it, or downloading the JSON export described in §14), the recipient gets that information at your direction. With Shields Law Firm, LLP - only if you separately engage them. Advoly LLC and Shields Law Firm, LLP are separate entities. Using Advoly does not give Shields Law Firm, LLP access to your Advoly data. Advoly has no feature that sends your information to Shields Law Firm, LLP or to any other attorney or law firm, and we do not share your information with them. The contents of your Advoly account - your children's records, your journal entries, your AI conversations, the encrypted body text of your documents - are not shared with Shields Law Firm, LLP. If you separately engage Shields Law Firm, LLP and want them to access your Advoly account, you must authorize that separately, in writing, and on terms set by your attorney engagement, not by these terms. For legal compliance, safety, and protection of the Services. We may disclose information where we believe in good faith that disclosure is reasonably necessary to: (a) respond to a lawful subpoena, court order, or other legal process or enforceable governmental request (Section 8 describes our general practices for legal demands); (b) comply with any other legal obligation - including reports of suspected child abuse or neglect that Texas law requires any person to make (see Section 8, "Safety and mandatory reporting"); (c) prevent imminent and serious harm to a person; (d) detect, prevent, or otherwise address fraud, abuse, security, or technical issues; (e) enforce our Terms of Service, including investigation of potential violations; or (f) protect the rights, property, or safety of Advoly, our users, or the public. For legal demands, where legally permitted, we may provide you notice before we disclose, and we seek to limit any disclosure to the information legally required - Section 8 describes these practices and the discretion we retain. With our professional advisors. We may share information with our own lawyers, insurers, accountants, auditors, and similar professional advisors, under obligations of confidentiality, where reasonably necessary to obtain their advice, to exercise or defend legal claims, or to maintain insurance coverage. In a corporate transaction. If Advoly LLC is acquired or merges with another company, or in connection with the diligence for such a transaction (under confidentiality), your information may be transferred to that company subject to this Privacy Policy. Where reasonably practicable, we will endeavor to notify you of a material change in the entity controlling your data. With your consent. Otherwise only with your explicit consent.
We receive law enforcement and other legal demands rarely. This section describes our general practices for responding to them. These are descriptions of how we generally approach legal demands - not promises of a particular response to any specific demand - and we reserve the right, at our sole discretion, to respond to each demand as we judge appropriate under the circumstances and as the law requires:
Our general practice is to require valid legal process - a subpoena, warrant, or court order, depending on the type of information requested - before disclosing user information in response to a demand. Where legally permitted, we may notify you of a demand for your records before disclosing, unless we are legally prohibited from doing so, an emergency requires immediate action, or we determine notice is otherwise inappropriate in the circumstances. We seek to limit disclosures to the specific information legally compelled, rather than the contents of your account by default. We reserve the right to object to, or move to quash, demands we consider overbroad or improperly issued, at our sole discretion. Nothing in this section obligates us to challenge any particular demand.
Safety and mandatory reporting
Texas law is unusual in one way that matters here: under Texas Family Code §261.101, every person - not just teachers and doctors - who has cause to believe that a child is being abused or neglected may be required to report it to the appropriate authorities. That duty applies to the people who work at Advoly, as people.
What that means in practice, stated plainly:
We do not monitor or search your account looking for evidence of abuse or neglect. That is not what the Services do, and it is not what this section is. But Advoly staff do sometimes see account content in the ordinary course of operating the Services - for example, when you ask support for help, or during the beta review described in §2.1. If, in that ordinary course, a staff member encounters something that gives them cause to believe a child is being abused or neglected, that staff member may be required by Texas law to make a report, and Advoly and its personnel will comply with applicable law. Nothing in this Privacy Policy limits the ability of Advoly or its personnel to comply with their legal obligations, or to make any report or disclosure that is permitted or required by law. One thing we want to say directly, because of who our users are: under the law, documenting what a school did wrong, advocating hard for your child, and describing your child's behaviors and struggles candidly so you can get them help are not abuse or neglect. They are the opposite - they are the ordinary work of special education advocacy, and they are what Advoly exists for.
Advoly is a parent-controlled tool. The user of Advoly is the parent or legal guardian (18+). The data stored in Advoly is, by category, often about a minor child - and an account may hold the records of up to four children, each in its own Child Profile.
We do not collect data directly from children. Children do not have Advoly accounts. The Services are not directed to children. We do not knowingly allow anyone under the age of 16 to provide personal information directly to the Services. If we learn that a child under 16 has provided information directly, we will delete the information when we become aware of it.
We treat child-subject data with COPPA-grade protections by analogy. COPPA, by its terms, regulates the online collection of personal information from children under 13 by website and app operators that direct services to children. Advoly does not direct services to children - we direct services to parents. The data we hold about a child comes from the parent, not the child. Even though the strict COPPA threshold is not triggered in this scenario, we apply COPPA-style protections voluntarily, per Child Profile:
Parental control. Only the parent/guardian account holder can access, modify, or delete a child's information. This control extends to the encrypted body-text store described in §10 and §13: only the owning parent's authenticated session can request decryption of body text scoped to that account. No advertising profiling. We do not build advertising profiles based on a child's information. No sharing with marketers. We do not share a child's information with marketers, advertisers, data brokers, or any third party for that party's own purposes. No public profiles. We do not create public profiles or directories from child information. Deletion on request. A parent or guardian can delete their account, including all Child Profiles, all child information, and the encrypted body text of every document they ever uploaded, at any time.
If a child you have entered into Advoly turns 18, the records remain in your parent account unless you delete them or transition them to that adult child's separate account (where supported by the Services). If a court enters an order changing custodial or guardianship authority, you must update your account; we cannot adjudicate disputes between custodial parties.
Advoly is not a HIPAA-covered entity. Under 45 CFR 160.103, HIPAA's covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with HHS-standardized transactions. Advoly is not any of those things.
That means HIPAA does not, by default, apply to your use of Advoly. The records you upload to Advoly are your records. They are not, in your hands, HIPAA-covered records, even if some of them came from a healthcare provider who is HIPAA-covered.
We are also aware of the regulatory landscape that applies to consumer apps that are not HIPAA-covered but handle sensitive information. Following the Federal Trade Commission's 2023 enforcement actions against consumer health apps that were not HIPAA-covered but acted in ways that suggested they were while sharing sensitive data with advertising platforms, the FTC has made clear that non-covered consumer apps must be honest about their HIPAA posture and must avoid practices - including unauthorized advertising-pixel-based data sharing - that would deceive consumers about how sensitive information is handled. Advoly's design and policies meet that standard. Advoly has no advertising at all.
We apply HIPAA-grade encryption and access controls voluntarily, not because we are required to. Specifically:
All data is encrypted in transit (TLS 1.2 or later). Account data, profile data, Events Log entries, and AI outputs are encrypted at rest at the database and storage layer (AES-256 or equivalent) by our backend host. The body text of uploaded educational records is column-level encrypted in a separate database table using AES-256-GCM with a random per-call initialization vector, with the encryption key held by Advoly LLC in our backend host's secrets manager (specifically, Supabase Vault). This is in addition to the host's default platform-level at-rest encryption. Database row-level access controls scope every read of body text to the authenticated owning user. Decryption is gated by a server-side authorization check; another user cannot request another user's body text under any circumstances. Advoly is designed for educational records. Medical records are not accepted - refused at upload when identified, and prohibited by our Terms of Service (§11.1). Educational evaluations are accepted, stored, and read by AI features on the same terms as other educational records. Advoly is not a covered entity or a business associate, and holds no protected health information subject to HIPAA. Medical and treatment records are refused at upload. §10.1 describes the three document categories and the honest limits of upload-time identification. Access by Advoly personnel to production systems is restricted, logged, and reviewed. (During the beta, the broader, disclosed, logged review described in §2.1 applies.) Our agreements with subprocessors that handle sensitive information require them to maintain comparable security postures.
Advoly sorts uploads into three categories. The category determines what we do with the document's contents:
Educational records - IEPs, prior written notices, behavior intervention plans, progress reports, report cards, ARD/IEP meeting notes, 504 plans, school correspondence. These are what Advoly is for. Body text is extracted (including via the OCR flow in §5.3 where needed), encrypted at rest with the Advoly-controlled key, and used to ground AI features for the owning Child Profile.
Educational evaluations. An evaluation done to decide school eligibility, placement, or services is an educational record, and Advoly treats it like one. Whether the school conducted it or you paid for it independently, its text is extracted, encrypted, and available to AI features the same way an IEP's text is. That includes the parts of the report that describe how your child performed.
What Maya will do. Tell you what the report actually says, including scores, standard scores, percentiles, and findings. Explain in general terms what a kind of assessment or score measures. Compare what the evaluation recommended against what your child's IEP actually provides, and say plainly when they don't match, which is usually the part that matters at an ARD.
What Maya will not do. Tell you what your child's individual results mean. Offer, confirm, or rule out a diagnosis. Second-guess or contradict the person who did the evaluation. Predict an eligibility decision. Those belong to the evaluator and to a licensed psychologist. When Maya explains what an assessment measures, she labels it as general information and says so on screen.
Where the text goes. Because Maya reads the full report, its contents, including scores and clinical findings, are sent to the AI providers named in our Subprocessors list when you use an AI feature. Those providers do not train their models on your information. This is a change from our earlier practice, under which an evaluation's contents were not sent at all.
Two honest limits. Whether a document is treated as an evaluation depends on the type you assign at upload and, as a fallback, its file name. That is best effort, so please label evaluations accurately; you can correct a document's type in Document Tracker at any time. And medical records are still refused at the door: an evaluation done for school placement is not a medical record, but a treatment note, hospital record, or clinical chart is. You can delete any document at any time.
Medical records - documents whose primary purpose is medical care (doctor's and hospital records, prescriptions, treatment plans, insurance and billing documents). Not accepted. If our system identifies an upload as a medical record, the upload is refused and the document is not saved to your account. We are not the place for medical records, and we'd rather say so at the door than store them carefully. Our Terms of Service (§11.1) also prohibit uploading them.
The honest limits. Category handling is governed by the document type assigned at upload - the type you choose (§5.2). Parents sometimes mislabel files (a scan named scan_001.pdf tells us nothing). A mislabeled document can be processed under the wrong category's rules - including extraction or OCR that the right category would not have received. What we describe here is the design above, plus the remedies: you can correct a document's type in Document Tracker, and you can delete any document at any time, which removes its extracted body text immediately by database cascade (§12). We have deliberately chosen this honest framing over absolute promises ("never," "structurally impossible") that no upload pipeline can truthfully make.
If you are a healthcare provider or health plan that wants to integrate Advoly into a clinical workflow that triggers HIPAA, contact us at support@advoly.com and we can discuss a Business Associate Agreement.
Advoly is not a school. FERPA, the Family Educational Rights and Privacy Act, governs schools, school districts, and state and local educational agencies. The records you upload to Advoly are your own copies of your child's educational records, held under your parental rights, not a school's FERPA record.
FERPA does not apply to Advoly's processing of your records, because Advoly is not a school official. We do not claim FERPA compliance, because that is not a defined legal status that applies to a parent-side tool.
What FERPA does give you, the parent. FERPA gives you, as the parent of a student under 18, specific rights as against your child's school: (a) the right to inspect and review your child's educational records, (b) the right to request that your child's school correct records you believe are inaccurate or misleading, (c) the right to control disclosure of personally identifiable information from those records, with limited exceptions, and (d) the right to file a complaint with the U.S. Department of Education's Family Policy Compliance Office if you believe your school has violated FERPA. Those rights run between you and your child's school. They do not run between you and Advoly. We mention them here because Advoly is a tool you may use to exercise those rights - for example, by helping you draft a records request to your child's school.
Parental access in Advoly. As the parent or guardian using the Services, you have the right to access, correct, and delete information in your account at any time. Those are Advoly's commitments to you, not FERPA obligations.
Different layers of the Services have different retention behavior. We describe each one separately so you know exactly what happens to your data and on what timeline. Advoly also maintains a written internal data-retention and deletion policy that implements the schedules in this section.
Live database (Advoly). When you delete a document, that document and its encrypted body-text row are deleted from our live database immediately, by database cascade - transactionally rather than eventually. When you delete your account, the same cascade runs across your full account record and every Child Profile on it: profiles, intake, Events Log entries, document metadata, document files, encrypted body text, chat history and its relevance flags, and the family-identity fields described in §5.4. Within 30 days, all production-system traces of your account are removed.
Backups. Advoly does not operate a separate backup system of its own. Backups are operated by our hosting platform (Lovable Cloud / Supabase), which retains automated daily database backups for a limited period - currently approximately 14 days. After a deletion, your data ages out of those platform backups within that window, and in no event later than 90 days. We do not restore deleted data from backups except to recover from a Service-wide incident.
Subprocessor retention windows (independent of Advoly). Some subprocessors retain data on their own schedules, which run independently of Advoly's deletion behavior:
AI provider. Requests we send on your behalf (grounding-context requests, classification requests, OCR requests, identity-extraction requests) are retained by the AI provider for a limited period for abuse-monitoring and trust-and-safety purposes before deletion. The current window for the current provider is described on our Subprocessors page. Once a request has been sent to the AI provider, the AI provider's retention timer for that request is not affected by Advoly's later deletion of your account.
Retention at a glance (by data category). In plain list form:
Account and profile data: kept while your account is active; deleted within 30 days of account deletion (production), and aged out of platform backups within ~14 days (90 days at the outside). Documents and extracted body text: kept until you delete the document or your account; live deletion is immediate by cascade; aged out of platform backups within ~14 days (90 days at the outside). Pocket Advocate chat history and per-message relevance flags: kept until you delete them or your account; the flags are deleted with the messages they describe. Family-identity fields (parent/guardian names, household address extracted from IEPs): kept for the life of the Child Profile; deleted with the Child Profile or the account. Extracted student name (§5.6): stored on the document's own record; kept for the life of that document and deleted with it, by the same immediate cascade that removes the document and its body text. AI-generated artifacts you save (IEP Audit analyses, drafted emails): same as documents - kept until you delete them or your account. Beta-period staff-access logs (§2.1): retained for 2 years after the beta program ends, as an accountability record. Records of legal acknowledgments you gave at signup (the not-legal-advice and beta acknowledgments): retained for up to 5 years after account deletion, as evidence of the acknowledgment. Account-deletion audit record (account_deletion_log): retained for up to 3 years after account deletion, as an accountability record; the deleted user's email address is scrubbed at that mark while a non-identifying audit row (deletion timestamp, initiator, reason) is preserved. Billing and transaction records: retained as required by tax and accounting law, even after account deletion. Aggregated, de-identified usage statistics that cannot be used to identify you: may be retained indefinitely. Waitlist information (§3.1): kept for as long as permitted by law, or until you ask us to remove it. On request we delete the entry. You can ask us by using the unsubscribe link in any email we send you, or by emailing support@advoly.com.
Legal and tax retention. We may retain records (transaction records, tax records, records subject to a litigation hold) longer than the schedules above where required by law, even after you delete your account.
You can delete individual records (a single document, a journal entry) at any time without deleting your account. A deleted document removes both the file and the encrypted body text by cascade. The 90-day Advoly-backup horizon and the subprocessor retention windows above also apply to per-record deletions.
We take security seriously, but no system is perfectly secure. We:
Encrypt data in transit (TLS 1.2 or later) and at rest (AES-256 or equivalent at the platform layer). Apply additional column-level encryption to the body text of uploaded documents using AES-256-GCM with a random per-call initialization vector. The encryption key is held by Advoly LLC in our backend host's secrets manager (Supabase Vault), not in application code or in any client-visible surface. Filter by document type before any decryption call, so that body text not eligible for AI processing, meaning medical records, is excluded before decryption rather than after. The honest scope of this protection: it is gated by the document type you assign at upload (see §5.2 and §10.1). Metadata reads, user-initiated exports (§14), and disclosures under §8 are governed by those sections, not by this filter. Restrict access to production systems to a small number of authorized personnel and log access. Operator decryption of body text, where it happens, is logged separately and reviewed. Apply principle-of-least-privilege to subprocessor configurations. Require strong authentication for our own internal systems. Maintain an incident response process and will notify you of a confirmed security incident affecting your data within the timeframe required by applicable law. Use written agreements that require subprocessors to maintain security postures consistent with their role.
Vulnerability disclosure (VDP). If you believe you have discovered a security vulnerability in the Services, we want to hear about it.
How to report: Email security@advoly.com with a description of the vulnerability and steps to reproduce. What to expect: We aim to acknowledge vulnerability reports within 5 business days and to provide a substantive response within 30 days. These timelines are goals, not guarantees. Safe harbor. As a matter of our discretion, we do not intend to pursue legal action against security researchers who, in our reasonable judgment, act in good faith, do not publicly disclose the vulnerability before we have had a reasonable opportunity to remediate, do not access or exfiltrate user data beyond what is necessary to demonstrate the vulnerability, and do not disrupt the Services for other users. This safe harbor is a statement of intended practice, applies only where all of these conditions are met as we reasonably determine, and does not bind law enforcement or any third party, authorize access to any user's data, or waive any right we may need to assert to protect our users. Scope. Reports about Advoly's own systems and Services are in scope. Reports about our subprocessors should be made to the subprocessor directly; we will assist where appropriate. Bug bounty. We do not yet operate a paid bug bounty program. If we add one, we will update this section.
You have rights regarding your information, regardless of where you live:
Access. You can view all of your User Content directly in Advoly. You can also download a complete JSON archive of your account through the export endpoint at /api/account/export. The archive covers every Child Profile on your account and includes your profile, intake, Events Log entries, document metadata, and the decrypted body text of the educational records in your account. A small number of documents may be stored without their text extracted - for example, a document awaiting your confirmation that it belongs to your child (see §5.6). Those appear in your export as metadata entries listing the file name, type, and date, with no body text. This is the mechanical fulfillment of the GDPR Article 15 right of access and the CCPA right to know - built into the product, not a manual process. Authentication is required; the export is scoped to the authenticated user. Each request is logged. If you cannot reach the export endpoint, you can also request an export by emailing support@advoly.com. Correction. You can correct inaccurate profile information - including a document's assigned type (§10.1) - directly in Advoly or by contacting support@advoly.com. Deletion. You can delete your account at any time through your account settings. Deletion runs as a cascade across the live database (immediate), file storage (immediate), and Advoly's encrypted body-text store (immediate, transactionally), covering all Child Profiles, chat history and relevance flags, and the family-identity fields described in §5.4. It propagates to Advoly's own backups within the 90-day window described in §12. Subprocessor retention windows that continue downstream of Advoly's deletion are also described in §12 and on the Subprocessors page. You can also email support@advoly.com to request deletion. Withdraw consent. Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing that already occurred. Object or restrict. Where applicable law gives you the right to object to or restrict processing, contact support@advoly.com. Complain. You can complain to a data protection authority where applicable.
Texas residents. Under the Texas Data Privacy and Security Act (TDPSA), Texas residents have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, and certain profiling. We do not engage in targeted advertising or sell personal data. To exercise these rights, contact support@advoly.com or use the in-product export and delete tools. (During the beta, all Advoly users are Texas residents - see §16.)
California residents. Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to know what personal information we collect, to access and delete it, to correct inaccuracies, to opt out of "sale" or "sharing" (we do not sell or share for cross-context behavioral advertising - see Section 7), and to limit use of sensitive personal information. To exercise these rights, contact support@advoly.com or use the in-product export and delete tools.
Other states. If you live in another state with a comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, and others as enacted), you have similar rights and can exercise them by contacting support@advoly.com or using the in-product export and delete tools.
We will not discriminate against you for exercising any privacy right.
The Advoly mobile app does not use third-party advertising trackers, and we do not use a third-party analytics provider. Our hosting platform (Lovable) provides built-in analytics for the published app - aggregate page views and performance metrics - which are not used for advertising or cross-site tracking.
The Advoly website at advoly.app uses essential cookies for authentication and session management. We do not use cookies for cross-site advertising. Where law requires a cookie consent mechanism, we will provide one.
Global Privacy Control (GPC) is a browser signal that opts you out of the sale of your data and of targeted advertising. Advoly does neither - we do not sell or share your personal information and we do not run advertising - so there is nothing for a GPC signal to opt you out of. If we ever introduced a practice that a GPC signal governs, we would honor the signal and update this policy first.
Geographic availability. During our beta period, Advoly is available to residents of Texas only. We do not currently accept new accounts from residents of other states, including states where we have not completed compliance work for state-specific health-data and privacy statutes (such as the California Confidentiality of Medical Information Act and Washington's My Health My Data Act). If you live outside Texas, you can join our waitlist at advoly.app/waitlist; we plan to notify waitlist members when Advoly expands to their state. What the waitlist form collects, how we use it, and how long we keep it are described in §3.1 and §12. The geographic restriction is enforced at signup based on the state of residence you provide.
International data transfers. The Services are operated from the United States. If you access them from outside the United States, your information will be transferred to and processed in the United States. We do not offer the Services to users in the European Union, the United Kingdom, or other jurisdictions where additional consents or registrations would be required. If we expand to new states or internationally, we intend to update this policy before any new region is added.
We may update this Privacy Policy. The "Last updated" date at the top reflects the most recent revision. We will endeavor to provide advance notice of material changes by email or by an in-product notice - ordinarily at least 14 days before they take effect. However, we may make changes effective immediately where we determine that is necessary to comply with law, address a security or safety issue, or prevent harm to the Services or our users.
We will not retroactively use information we previously collected for a new purpose that materially changes the nature of how it is processed without obtaining your consent (or providing legally required notice and opt-out).
General privacy questions: support@advoly.com Security issues: security@advoly.com HIPAA / BAA inquiries (for healthcare providers integrating Advoly): support@advoly.com Subscribe to subprocessor change notifications: support@advoly.com Mailing: Advoly LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731
We aim to respond to privacy inquiries within 10 business days